CVE-2026-81578
PaperCut NG Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-81578 is an improper access control (authentication bypass) vulnerability in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions before access validation checks complete, allowing an unauthenticated attacker to modify certain system configurations. The vulnerability affects PaperCut MF/NG versions prior to 24.1.10, 25.0.13, and 26.0.5, and was publicly disclosed on August 28, 2026. It carries a CVSS v4.0 base score of 8.8 (High) (GitHub Advisory, PaperCut Advisory).

Détails techniques

The root cause is classified as CWE-305 (Authentication Bypass by Primary Weakness), where the authentication algorithm itself is sound but a separate weakness in the implementation allows it to be bypassed. Specifically, the PaperCut web management interface — built on the Apache Tapestry framework — processes certain administrative requests in a way that backend actions are triggered before access validation is fully completed, a condition described as "Tapestry request confusion" by researchers (CTI Pilot). The attack vector is fully network-based, requires no privileges, no user interaction, and no special attack requirements, making it trivially automatable. CVE-2026-81578 is frequently chained with a companion vulnerability, CVE-2026-82078 (dynamic class loading), to achieve pre-authentication remote code execution (The Hacker News, Dev.to Analysis).

Impact

Successful exploitation allows an unauthenticated remote attacker to modify system configurations on the PaperCut MF/NG server, with high integrity impact and low confidentiality and availability impact on the vulnerable system. When chained with CVE-2026-82078, attackers can escalate to full pre-authentication remote code execution, enabling complete server compromise, credential theft, lateral movement within the network, and potential ransomware deployment (Huntress, eSentire). PaperCut is widely deployed in enterprise, education, and government environments, meaning a large number of internet-facing print management servers are at risk (Rapid7).

Exploitabilité

CVE-2026-81578 has been actively exploited in the wild as a zero-day, with exploitation reported prior to the initial patch release and continuing after the first fix was found to be bypassable, necessitating a second emergency patch (BleepingComputer, SecurityWeek). A public detection/scanning tool (not a full exploit) is available on GitHub (GitHub PoC), and Nessus detection plugins (IDs 341347 and 341348) have been released. The EPSS score is approximately 0.39% (32nd percentile). The NVD SSVC assessment marks the vulnerability as automatable. No specific threat actor attribution has been publicly confirmed, though exploitation has been reported by multiple threat intelligence sources including Threadlinqs and ReliaQuest (Threadlinqs).

Étapes d’exploitation

  1. Reconnaissance: Use Shodan, Censys, or similar tools to identify internet-facing PaperCut MF/NG web management interfaces (typically on TCP port 9191 or 9192) running versions prior to 24.1.10, 25.0.13, or 26.0.5.
  2. Fingerprint the target: Send HTTP requests to the PaperCut web interface to confirm the version and identify the Tapestry-based administrative endpoints.
  3. Exploit authentication bypass (CVE-2026-81578): Craft an HTTP request targeting an administrative function endpoint in a manner that triggers backend processing before the access validation check completes, effectively bypassing authentication due to the Tapestry request confusion weakness (CTI Pilot).
  4. Modify system configuration: Use the unauthenticated access to alter system configurations — for example, enabling scripting features or modifying printer/user settings that facilitate further exploitation.
  5. Chain with CVE-2026-82078 for RCE: Leverage the configuration modification to exploit the companion dynamic class loading vulnerability (CVE-2026-82078), loading a malicious class or script to achieve pre-authentication remote code execution on the server (The Hacker News, Dev.to Analysis).
  6. Post-exploitation: Execute arbitrary commands as the PaperCut service account, deploy web shells or malware, harvest credentials, and move laterally within the network (Huntress).

Indicateurs de compromis

  • Network: Unusual unauthenticated HTTP/HTTPS requests to PaperCut administrative endpoints (ports 9191/9192) from external or unexpected IP addresses; outbound connections from the PaperCut server to unknown external hosts.
  • Logs: PaperCut application logs showing administrative actions (configuration changes) with no corresponding authenticated session; repeated requests to administrative API endpoints without valid session tokens; errors related to Tapestry request processing.
  • File System: Unexpected scripts, JAR files, or web shells placed in the PaperCut installation directory or temp directories; new or modified configuration files in the PaperCut data directory.
  • Process: Unusual child processes spawned by the PaperCut server process (e.g., cmd.exe, powershell.exe, bash, curl, wget); unexpected Java class loading events in application logs.
  • Elastic Detection Rules: Elastic has published detection rules for this vulnerability (Elastic Detection Rules).

Atténuation et solutions de contournement

PaperCut has released patched versions addressing CVE-2026-81578: 24.1.10, 25.0.13, and 26.0.5. Notably, the initial patch was found to be bypassable, and PaperCut issued a second emergency patch — organizations should ensure they are running the latest fixed release and not just the first patch (BleepingComputer, PaperCut Advisory). As a network-level workaround, restrict access to the PaperCut web management interface (ports 9191/9192) to trusted IP addresses only, and avoid exposing the admin interface directly to the internet. Monitor administrative function requests for anomalous unauthenticated activity as an additional detection measure.

Réactions de la communauté

The vulnerability generated significant industry attention, with Rapid7, Huntress, eSentire, and SecurityWeek all publishing analyses and emergency advisories shortly after disclosure (Rapid7, Huntress, SecurityWeek). The fact that the initial patch was bypassed and a second emergency patch was required drew particular criticism and concern from the security community, with coverage from BleepingComputer, The Hacker News, The Record, and multiple national CERTs including NHS Digital (UK) and the Canadian Centre for Cyber Security (NHS Digital, Canadian CCCS). Social media discussion was active on LinkedIn and Mastodon, with researchers highlighting the pre-auth RCE chain formed by combining CVE-2026-81578 with CVE-2026-82078.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté PaperCut NG Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-82078CRITICAL9.4
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
OuiOuiAug 28, 2026
CVE-2026-81578HIGH8.8
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
OuiOuiAug 28, 2026
CVE-2026-6418MEDIUM4.6
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_ng
NonOuiMay 05, 2026
CVE-2026-6180MEDIUM4.1
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
NonOuiMay 05, 2026
CVE-2026-4794LOW2.1
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
NonOuiMar 31, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités